Fetching the paper…
Reading the bibliography…
Deep neural networks (DNN) are known to be vulnerable to adversarial attacks.
Multivariate stochastic approximation using a simultaneous perturbation gradient approximation
James C Spall et al · 1992
Earlier work this paper cites.
Learning algorithms for classification: A comparison on handwritten digit recognition
Yann LeCun, LD Jackel, Léon Bottou, Corinna Cortes, John S Denker, Harris Drucker, Isabelle Guyon, UA Muller, Eduard Sackinger, Patrice Simard, et al · 1995
Earlier work this paper cites.
An algorithm for total variation minimization and applications
Antonin Chambolle. 2004 · 2004
Earlier work this paper cites.
Learning multiple layers of features from tiny images
Alex Krizhevsky and Geoffrey Hinton. 2009 · 2009
Earlier work this paper cites.
Man vs. computer: Benchmarking machine learning algorithms for traffic sign recognition
J. Stallkamp, M. Schlipsing, J. Salmen, and C. Igel. 2012 · 2012
Earlier work this paper cites.
Explaining and harnessing adversarial examples
Ian J Goodfellow, Jonathon Shlens, and Christian Szegedy. 2014 · 2014
Earlier work this paper cites.
Intriguing properties of neural networks. In Proc. of ICLR
Christian Szegedy, Wojciech Zaremba, Ilya Sutskever, Joan Bruna, Dumitru Erhan, Ian Goodfellow, and Rob Fergus. 2014 · 2014
Earlier work this paper cites.
Deep face recognition.. In bmvc , Vol. 1. 6
Omkar M Parkhi, Andrea Vedaldi, Andrew Zisserman, et al · 2015
Earlier work this paper cites.
Defensive distillation is not robust to adversarial examples
Nicholas Carlini and David Wagner. 2016 · 2016
Earlier work this paper cites.
Ms-celeb-1m: A dataset and benchmark for large-scale face recognition. In European Conference on Computer Vision . Springer, 87–102
Yandong Guo, Lei Zhang, Yuxiao Hu, Xiaodong He, and Jianfeng Gao. 2016 · 2016
Earlier work this paper cites.
Deep residual learning for image recognition. In Proc. of CVPR
Kaiming He, Xiangyu Zhang, Shaoqing Ren, and Jian Sun. 2016 · 2016
Earlier work this paper cites.
Adversarial examples in the physical world
Alexey Kurakin, Ian Goodfellow, and Samy Bengio. 2016 · 2016
Earlier work this paper cites.
Distillation as a defense to adversarial perturbations against deep neural networks. In Proc. of IEEE S&P
Nicolas Papernot, Patrick McDaniel, Xi Wu, Somesh Jha, and Ananthram Swami. 2016 · 2016
Earlier work this paper cites.
Accessorize to a crime: Real and stealthy attacks on state-of-the-art face recognition. In Proc. of CCS
Mahmood Sharif, Sruti Bhagavatula, Lujo Bauer, and Michael K Reiter. 2016 · 2016
Earlier work this paper cites.
Improving the robustness of deep neural networks via stability training. In Proc. of CVPR
Stephan Zheng, Yang Song, Thomas Leung, and Ian Goodfellow. 2016 · 2016
Earlier work this paper cites.
Adversarial examples are not easily detected: Bypassing ten detection methods
Nicholas Carlini and David Wagner. 2017a · 2017
Earlier work this paper cites.
Magnet and efficient defenses against adversarial attacks are not robust to adversarial examples
Nicholas Carlini and David Wagner. 2017b · 2017
Earlier work this paper cites.
Targeted Backdoor Attacks on Deep Learning Systems Using Data Poisoning
Xinyun Chen, Chang Liu, Bo Li, Kimberly Lu, and Dawn Song. 2017 · 2017
Cited alongside, same era.
Badnets: Identifying vulnerabilities in the machine learning model supply chain. In Proc. of Machine Learning and Computer Security Workshop
Tianyu Gu, Brendan Dolan-Gavitt, and Siddharth Garg. 2017 · 2017
Cited alongside, same era.
Adversarial example defenses: Ensembles of weak defenses are not strong. In Proc. of WOOT
Warren He, James Wei, Xinyun Chen, Nicholas Carlini, and Dawn Song. 2017 · 2017
Cited alongside, same era.
Provable defenses against adversarial examples via the convex outer adversarial polytope. In Proc. of NeurIPS
J. Zico Kolter and Eric Wong. 2017 · 2017
Cited alongside, same era.
Adversarial machine learning at scale. In Proc. of ICLR
Alexey Kurakin, Ian Goodfellow, and Samy Bengio. 2017 · 2017
Cited alongside, same era.
Towards deep learning models resistant to adversarial attacks. In Proc. of ICLR
Aleksander Madry, Aleksandar Makelov, Ludwig Schmidt, Dimitris Tsipras, and Adrian Vladu. 2018 · 2018
Later among the works it cites.
Defensegan: Protecting classifiers against adversarial attacks using generative models. In Proc. of ICLR
P. Samangouei, M. Kabkab, and R. Chellappa. 2018 · 2018
Later among the works it cites.
Pixeldefend: Leveraging generative models to understand and defend against adversarial examples. In Proc. of ICLR
Y. Song, T. Kim, S. Nowozin, S. Ermon, and N. Kushman. 2018 · 2018
Later among the works it cites.
When Does Machine Learning FAIL? Generalized Transferability for Evasion and Poisoning Attacks. In Proc. of USENIX Security
Octavian Suciu, Radu Mărginean, Yiğitcan Kaya, Hal Daumé III, and Tudor Dumitraş. 2018 · 2018
Later among the works it cites.
Adversarial risk and the dangers of evaluating against weak attacks
Jonathan Uesato, Brendan O’Donoghue, Aaron van den Oord, and Pushmeet Kohli. 2018 · 2018
alphaXiv searches the wider corpus for related work and actual follow-ups.
alphaXiv is searching for related work…
Magnet: a two-pronged defense against adversarial examples. In Proc. of CCS
Dongyu Meng and Hao Chen. 2017 · 2017
Cited alongside, same era.
Practical black-box attacks against machine learning. In Proc. of AsiaCCS
Nicolas Papernot, Patrick McDaniel, Ian Goodfellow, Somesh Jha, Z. Berkay Celik, and Ananthram Swami. 2017 · 2017
Cited alongside, same era.
Efficient defenses against adversarial attacks. In Proc. of AISec
Valentina Zantedeschi, Maria-Irina Nicolae, and Ambrish Rawat. 2017 · 2017
Cited alongside, same era.
Turning your weakness into a strength: Watermarking deep neural networks by backdooring. In Proc. of USENIX Security
Yossi Adi, Carsten Baum, Moustapha Cisse, Benny Pinkas, and Joseph Keshet. 2018 · 2018
Cited alongside, same era.
Obfuscated gradients give a false sense of security: Circumventing defenses to adversarial examples. In Proc. of ICML
Anish Athalye, Nicholas Carlini, and David Wagner. 2018 · 2018
Cited alongside, same era.
Thermometer encoding: One hot way to resist adversarial examples. In Proc. of ICLR
J. Buckman, A. Roy, C. Raffel, and I. Goodfellow. 2018 · 2018
Cited alongside, same era.
Vggface2: A dataset for recognising faces across pose and age. In 2018 13th IEEE International Conference on Automatic Face & Gesture Recognition (FG 2018) . IEEE, 67–74
Qiong Cao, Li Shen, Weidi Xie, Omkar M Parkhi, and Andrew Zisserman. 2018a · 2018
Cited alongside, same era.
Later among the works it cites.
Mitigating adversarial effects through randomization. In Proc. of ICLR
C. Xie, J. Wang, Z. Zhang, Z. Ren, and A. Yuille. 2018 · 2018
Later among the works it cites.
Feature squeezing: Detecting adversarial examples in deep neural networks. In Proc. of NDSS
Weilin Xu, David Evans, and Yanjun Qi. 2018 · 2018
Later among the works it cites.
Protecting intellectual property of deep neural networks with watermarking. In Proc. of AsiaCCS
Jialong Zhang, Zhongshu Gu, Jiyong Jang, Hui Wu, Marc Ph Stoecklin, Heqing Huang, and Ian Molloy. 2018 · 2018
Later among the works it cites.
On Evaluating Adversarial Robustness
Nicholas Carlini, Anish Athalye, Nicolas Papernot, Wieland Brendel, Jonas Rauber, Dimitris Tsipras, Ian Goodfellow, Aleksander Madry, and Alexey Kurakin. 2019 · 2019
Closest in time.
Why do adversarial attacks transfer? explaining transferability of evasion and poisoning attacks. In Proc. of USENIX Security . 321–338
Ambra Demontis, Marco Melis, Maura Pintor, Matthew Jagielski, Battista Biggio, Alina Oprea, Cristina Nita-Rotaru, and Fabio Roli. 2019 · 2019
Closest in time.
ABS: Scanning neural networks for back-doors by artificial brain stimulation. In Proceedings of the 2019 ACM SIGSAC Conference on Computer and Communications Security . ACM, 1265–1282
Yingqi Liu, Wen-Chuan Lee, Guanhong Tao, Shiqing Ma, Yousra Aafer, and Xiangyu Zhang. 2019 · 2019
Closest in time.
NIC: Detecting Adversarial Samples with Neural Network Invariant Checking. In Proc. of NDSS
Shiqing Ma, Yingqi Liu, Guanhong Tao, Wen-Chuan Lee, and Xiangyu Zhang. 2019 · 2019
Closest in time.
Defending Neural Backdoors via Generative Distribution Modeling
Ximing Qiao, Yukun Yang, and Hai Li. 2019 · 2019
Closest in time.
Are adversarial examples inevitable?. In Proc. of ICLR
Ali Shafahi, W Ronny Huang, Christoph Studer, Soheil Feizi, and Tom Goldstein. 2019 · 2019
Closest in time.
Neural Cleanse: Identifying and Mitigating Backdoor Attacks in Neural Networks. In Proc. of IEEE S&P
Bolun Wang, Yuanshun Yao, Shawn Shan, Huiying Li, Bimal Viswanath, Haitao Zheng, and Ben Y. Zhao. 2019 · 2019
Closest in time.
Gotta Catch ’Em All: Using Honeypots to Catch Adversarial Attacks on Neural Networks
Shawn Shan, Emily Wenger, Bolun Wang, Bo Li, Haitao Zheng, and Ben Y. Zhao. 2020 · 2020
Closest in time.